Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Digital Forensics

Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.

Kitploit recommended

Top tools

10 selected
autopsy preview#1

autopsy

GitHubsleuthkit/autopsy
3.3k4 months ago
sleuthkit preview#2

sleuthkit

GitHubsleuthkit/sleuthkit
3.1k21 days ago
volatility3 preview#3

volatility3

GitHubvolatilityfoundation/volatility3
4.3k15h 53m ago
plaso preview#4

plaso

GitHublog2timeline/plaso
2.1k12 days ago
bulk_extractor preview#5

bulk_extractor

GitHubsimsong/bulk_extractor
1.4k8 days ago
velociraptor preview#6

velociraptor

GitHubvelocidex/velociraptor
4.2k15h 8m ago
timesketch preview#7

timesketch

GitHubgoogle/timesketch
3.4k1 day ago
mvt preview#8

mvt

GitHubmvt-project/mvt
13.0k19h 32m ago
androidqf preview#9

androidqf

GitHubmvt-project/androidqf
2308 days ago
avml preview#10

avml

GitHubmicrosoft/avml
1.1k20 days ago
NewestRelevanceMost popularRecently updated
1192 results
PacketStreamer preview
Archived

PacketStreamer

GitHubdeepfence/packetstreamer

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐

packet-sniffing-analysiscontainer-securitynetwork-mapping+6
1.9k2 years ago
osxcollector preview
Archived

osxcollector

GitHubyelparchive/osxcollector

A forensic evidence collection & analysis toolkit for OS X

disk-forensicsosintmemory-forensics+3
1.9k7 years ago
stenographer preview
Archived

stenographer

GitHubgoogle/stenographer

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

packet-sniffing-analysisnetwork-forensicsforensics+3
1.8k5 years ago
pyrebox preview
Archived

pyrebox

GitHubcisco-talos/pyrebox

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

dynamic-analysis-sandboxingmemory-forensicsreverse-engineering+5
1.7k2 years ago
pe_tree preview
Archived

pe_tree

GitHubblackberry/pe_tree

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

memory-forensicsvulnerability-analysisreverse-engineering+5
1.3k4 years ago
ThreatPursuit-VM preview
Archived

ThreatPursuit-VM

GitHubmandiant/threatpursuit-vm

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

osintvulnerability-analysisinformation-gathering+8
1.3k3 years ago
mig preview
Archived

mig

GitHubmozilla/mig

Distributed & real time digital forensics at the speed of the cloud

disk-forensicsmemory-forensicsvulnerability-analysis+6
1.2k6 years ago
usbrip preview
Archived

usbrip

GitHubsnovvcrash/usbrip

Tracking history of USB events on GNU/Linux

forensicsdigital-forensicsthreat-intelligence+2
1.2k3 years ago
LSB-Steganography preview
Archived

LSB-Steganography

GitHubrobindavid/lsb-steganography

Python program to steganography files into images using the Least Significant Bit.

encryption-decryption-toolsdata-exfiltrationforensics+3
9574 years ago
PPLdump preview
Archived

PPLdump

GitHubitm4n/ppldump

Dump the memory of a PPL with a userland exploit

privilege-escalationmemory-forensicsexploitation+3
8934 years ago
SilkETW preview
Archived

SilkETW

GitHubmandiant/silketw

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

defensive-toolsmemory-forensicsforensics+8
8523 years ago
grapl preview
Archived

grapl

GitHubgrapl-security/grapl

Graph platform for Detection and Response

reconnaissancethreat-feeds-aggregatorsforensics+8
6993 years ago
Mandiant-Azure-AD-Investigator preview
Archived

Mandiant-Azure-AD-Investigator

GitHubmandiant/mandiant-azure-ad-investigator

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

digital-forensicscloud-securitythreat-intelligence+4
6503 years ago
DumpChromeSecrets preview
Archived

DumpChromeSecrets

GitHubmaldev-academy/dumpchromesecrets

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

password-crackingreconnaissancedata-exfiltration+8
5588 months ago
linux-explorer preview
Archived

linux-explorer

GitHubintezer/linux-explorer

Easy-to-use live forensics toolbox for Linux endpoints

osintmemory-forensicsvulnerability-analysis+7
4052 years ago
android-forensics preview
Archived

android-forensics

GitHubnowsecure/android-forensics

Open source Android Forensics app and framework

android-securityforensicsmobile-forensics+2
39711 years ago
matrix-rs preview
Archived

matrix-rs

GitHubmemn0ps/matrix-rs

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

memory-forensicsdynamic-code-analysisids-ips-evasion+3
3563 months ago
dfir-toolkit preview
Archived

dfir-toolkit

GitHubdfir-dd/dfir-toolkit

CLI tools for forensic investigation of Windows artifacts

disk-forensicsforensicsdigital-forensics+2
3551 year ago
Previous1…64656667Next